PRIVACY & TERMS

Effective date: 20 July 2026

 

1. INTRODUCTION

This Privacy Policy explains how KM Racing s.r.o., operating under the MM Technology brand, processes personal data in connection with the website www.mmtechnology.com.

We process personal data in accordance with Regulation (EU) 2016/679, the General Data Protection Regulation (“GDPR”), Act No. 110/2019 Coll., on Personal Data Processing, and other applicable legislation.

This Privacy Policy applies to visitors to our website, persons who contact us through the website or by e-mail, prospective customers, customers, suppliers and other business partners.

 

2. DATA CONTROLLER

The controller of personal data is:

KM Racing s.r.o. Company ID No.: 27630277 Registered office: U Šalamounky 769/41, Košíře, 158 00 Prague, Czech Republic Brand: MM Technology Website: www.mmtechnology.com E-mail: info@mmtechnology.com

Any questions or requests relating to personal data may be sent to info @mmtechnology.com.

 

3. PERSONAL DATA WE PROCESS

Depending on how you use the website and communicate with us, we may process the following categories of personal data:

  1. identification data, in particular your name;
  2. contact data, in particular your e-mail address, telephone number and country;
  3. communication data, including the contents of your message, enquiry, request and subsequent correspondence;
  4. business and contractual data, including information concerning a requested product, vehicle, technology, service, proposed cooperation or contractual relationship;
  5. technical data, including IP address, browser type, device type, operating system, language settings, approximate location derived from the IP address, date and time of access and technical logs;
  6. website usage data, including information about pages visited, interactions with the website, clicks, scrolling, session duration, traffic source and other information concerning use of the website;
  7. marketing data, including online identifiers, advertising identifiers, information about interaction with our advertisements and inclusion in advertising or remarketing audiences;
  8. consent data, including the date, time, scope and technical record of consent granted or refused through the cookie consent tool.

We do not intentionally request special categories of personal data through the website. Please do not include health data, biometric data, political opinions, religious beliefs or other sensitive information in the contact form unless this is strictly necessary.

 

4. CONTACT FORM AND BUSINESS ENQUIRIES

The contact form may contain the following fields:

name; e-mail address; telephone number; country; message.

Information submitted through the contact form is stored in the website administration and is also delivered to info@mmtechnology.com. Where relevant, the information may subsequently be entered into an internal customer relationship management system for the purpose of handling and recording the enquiry.

We process this information for the following purposes:

responding to your enquiry; assessing your request; preparing an offer; taking steps at your request before entering into a contract; communicating about possible cooperation; entering into and performing a contract; protecting and enforcing our legal rights.

The legal basis is:

Article 6(1)(b) GDPR, where processing is necessary to take steps at your request before entering into a contract or to perform a contract;

Article 6(1)(f) GDPR, based on our legitimate interest in responding to general enquiries, managing business communications, keeping reasonable records of communications and protecting our legal rights.

Providing information through the contact form is voluntary. However, without the required contact information, we may be unable to respond to your enquiry.

The contact form is not used to subscribe you to a newsletter or other electronic marketing communications.

 

5. WEBSITE OPERATION AND SECURITY

We process technical information and server logs to:

display and operate the website; ensure the stability and security of the website; detect technical errors; prevent fraud, spam, attacks and misuse; protect the website, forms and information systems; investigate security incidents.

The legal basis is Article 6(1)(f) GDPR, based on our legitimate interest in maintaining a secure, reliable and functional website.

Where a storage or access technology is strictly necessary to provide a service expressly requested by the visitor or to ensure the basic operation and security of the website, it may be used without consent to the extent permitted by applicable law.

 

6. GOOGLE RECAPTCHA

We use Google reCAPTCHA to protect the contact form against automated submissions, spam and misuse.

When reCAPTCHA is used, Google may process technical information such as your IP address, device and browser information, website interactions and other information necessary to assess whether the interaction is made by a person or an automated system.

The purpose of this processing is website and form security. The legal basis is Article 6(1)(f) GDPR, based on our legitimate interest in protecting the website and our systems against spam, abuse and cyber threats.

Where technically possible, reCAPTCHA should be loaded only when necessary for use of the relevant form. Its implementation must not be used for advertising or unrelated tracking purposes.

The provider is generally Google Ireland Limited for users in the European Economic Area and Switzerland. Google may involve affiliated companies and service providers outside the European Economic Area.

 

7. ANALYTICS AND USER BEHAVIOUR

Subject to your consent, we may use analytics tools to understand how the website is used, improve its structure and content, identify technical or usability issues and evaluate website performance.

These tools may include:

Google Analytics; Hotjar; Google Tag Manager, where used to deploy or manage analytical tags.

Google Analytics may process information such as online identifiers, IP-derived location, device and browser information, pages visited, actions performed, session duration and traffic source.

Hotjar may process information about the way visitors interact with the website, including clicks, scrolling, navigation patterns, device information, screen size and session information. Depending on the configured Hotjar features, this may include heatmaps and session recordings.

We will configure Hotjar to suppress or exclude form entries, passwords and other information that should not be captured. Contact form contents must not be intentionally recorded through Hotjar.

Analytical tools are used only after you grant consent through the cookie consent tool.

The legal basis is Article 6(1)(a) GDPR.

You may withdraw your consent at any time through the Cookie Settings link available on the website. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

 

8. ADVERTISING, CONVERSION MEASUREMENT AND REMARKETING

Subject to your consent, we may use advertising and remarketing technologies to:

measure the effectiveness of advertising campaigns; record conversions and interactions with advertisements; understand how visitors reach the website; create advertising audiences; display advertisements to persons who previously interacted with our website; limit the frequency of advertisements; improve the relevance of advertising.

These tools may include:

Google Ads; Meta Pixel; LinkedIn Insight Tag; Google Tag Manager, where used to deploy or manage advertising tags.

These providers may associate information collected through the website with information obtained from their own services, subject to their respective terms, account settings and privacy policies.

Marketing and remarketing technologies are used only after you grant consent through the cookie consent tool.

The legal basis is Article 6(1)(a) GDPR.

You may withdraw your consent at any time through the Cookie Settings link available on the website.

 

9. CUSTOMER RELATIONSHIP MANAGEMENT SYSTEM

Information received through enquiries and subsequent business communication may be entered into a customer relationship management system used by KM Racing s.r.o.

The CRM system may contain identification data, contact data, the contents and history of communications, information about requested products or services, the status of negotiations and information necessary to manage a prospective or existing business relationship.

The purposes of processing are:

handling enquiries; maintaining an overview of business communications; preparing and managing offers; managing prospective and existing customer relationships; performing contracts; protecting legal claims.

The legal basis is Article 6(1)(b) GDPR and Article 6(1)(f) GDPR.

The specific CRM provider may be changed as part of our internal technical infrastructure. Any provider that processes personal data on our behalf will be bound by appropriate data processing and confidentiality obligations.

 

10. LOCALLY HOSTED CONTENT

Videos made available directly through the website are hosted on our own server or infrastructure and are not embedded from YouTube or Vimeo.

Fonts are also hosted locally and are not loaded directly from Google Fonts servers.

This arrangement is intended to reduce unnecessary transmission of visitor information to third-party content providers.

 

11. RECIPIENTS OF PERSONAL DATA

Personal data may be made available to recipients that provide services necessary for the operation of our business and website, in particular:

web hosting and infrastructure providers, including ACTIVE 24; website administration and IT support providers; providers of e-mail and communication services; providers of analytics and user behaviour tools, including Google and Hotjar; advertising providers, including Google, Meta and LinkedIn; providers of security and anti-spam services, including Google reCAPTCHA; providers of CRM or business administration systems; accounting, tax, legal and other professional advisers; public authorities where disclosure is required by law.

We technically administer the website internally. External recipients receive personal data only to the extent necessary for the relevant purpose.

Where a recipient acts as our processor, processing is governed by a data processing agreement or other legally required safeguards.

 

12. TRANSFERS OUTSIDE THE EUROPEAN ECONOMIC AREA

Some providers, particularly global technology and advertising providers, may process or make personal data accessible in countries outside the European Economic Area.

Where personal data is transferred outside the European Economic Area, we rely on an applicable legal transfer mechanism, which may include:

an adequacy decision adopted by the European Commission; the EU-U.S. Data Privacy Framework, where applicable to the relevant certified recipient; standard contractual clauses adopted by the European Commission; additional contractual, organisational or technical safeguards.

Information about the transfer mechanisms used by a particular provider is available in that provider’s privacy and data transfer documentation.

 

13. RETENTION PERIODS

We retain personal data only for as long as necessary for the relevant purpose.

Unless a longer period is required by law or justified in an individual case, the following periods generally apply:

  1. ordinary enquiries that do not lead to further negotiations or cooperation: up to 12 months after the enquiry has been resolved;
  2. relevant business negotiations and related communications: for the duration of the negotiations and generally for up to 3 years after the negotiations or communication have ended;
  3. contractual relationships: for the duration of the contractual relationship and thereafter for the period required by legal, accounting, tax and limitation rules;
  4. information retained for legal claims: generally for the applicable limitation period and, where a dispute or proceeding has commenced, until its final conclusion;
  5. technical and security logs: for the period reasonably necessary for security and troubleshooting, generally no longer than 6 months unless a security incident requires longer retention;
  6. consent records: for the period necessary to demonstrate compliance, generally for the duration of the relevant consent and up to 3 years after its withdrawal or expiry;
  7. information collected through cookies and similar technologies: according to the lifetime of the relevant technology stated in the Cookie Policy or cookie consent tool.

Data may be deleted or anonymised earlier where it is no longer needed.

 

14. SOURCES OF PERSONAL DATA

We generally obtain personal data:

directly from you; through the contact form; through e-mail, telephone or other business communication; automatically through the website, subject to your cookie choices; from advertising and analytics providers; from publicly available business sources where relevant to an existing or potential business relationship.

 

15. AUTOMATED DECISION-MAKING

We do not use information submitted through the contact form to make decisions that produce legal effects concerning you or similarly significantly affect you solely by automated means.

Advertising providers may use automated systems to select audiences or display advertisements. Such activities are subject to your consent and to the settings and practices of the relevant provider.

 

16. YOUR RIGHTS

Subject to the conditions set out in applicable law, you have the right to:

request confirmation as to whether we process your personal data;

obtain access to your personal data;

request correction of inaccurate or incomplete personal data;

request erasure of personal data;

request restriction of processing;

receive personal data in a structured, commonly used and machine-readable format and request its transmission to another controller where the right to data portability applies;

object to processing based on legitimate interests;

withdraw consent at any time where processing is based on consent;

lodge a complaint with a supervisory authority.

Where processing is based on our legitimate interests, you may object at any time on grounds relating to your particular situation. We will stop the processing unless we demonstrate compelling legitimate grounds that override your interests, rights and freedoms or the processing is necessary for the establishment, exercise or defence of legal claims.

Where personal data is processed for direct marketing purposes, you have the right to object to such processing at any time.

Withdrawal of consent does not affect the lawfulness of processing carried out before the consent was withdrawn.

 

17. EXERCISING YOUR RIGHTS

Requests relating to personal data may be sent to:

info@mmtechnology.com

We may request information reasonably necessary to verify your identity. We will respond within the period required by applicable law.

 

18. COMPLAINTS

You have the right to lodge a complaint with the competent supervisory authority.

In the Czech Republic, the supervisory authority is:

Office for Personal Data Protection Pplk. Sochora 27 170 00 Prague 7 Czech Republic

 

19. SECURITY

We use appropriate technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.

These measures may include:

encrypted HTTPS communication; access controls; password protection; role-based access; software updates; backups; logging and monitoring; restrictions on access to website administration and business systems; internal confidentiality requirements.

No information system is completely secure. We therefore continuously assess and adjust security measures according to the nature and risks of the processing.

 

20. THIRD-PARTY WEBSITES

The website may contain links to websites operated by third parties. We are not responsible for the privacy practices or content of such websites. You should review the privacy information provided by the relevant third party.

 

21. CHANGES TO THIS PRIVACY POLICY

We may update this Privacy Policy where our processing activities, service providers, technical setup or legal obligations change.

The current version will always be published on the website together with its effective date.